Government Technology Review
CIO StrategyLong read

Government Technology Budget Cycles and Funding Mechanisms

Seventy-nine percent of federal IT spending maintains old systems instead of building new ones.

Correspondent · · 10 min read
Cover illustration for “Government Technology Budget Cycles and Funding Mechanisms”
CIO Strategy · August 27, 2026 · 10 min read · 2,344 words

Government technology spending in the United States is projected to hit $357 billion in 2026 across all levels of government, and federal IT alone came in at $102.31 billion in FY2025, up roughly 8% a year since FY2022. That figure runs through a process that looks nothing like how a private company decides to buy software; it functions instead as the plumbing budget for services millions of people rely on every single day. This piece walks through how that process actually works, layer by layer, and why the pace of government tech change is baked into the calendar itself rather than into anyone's reluctance to modernize.

How the federal fiscal year is structured, and when decisions actually get made

The federal fiscal year runs October 1 through September 30, not January to December, which trips up more people than you'd expect, including some who work in the industry.

Budget formulation for a given fiscal year starts about 18 months before that year even begins, kicked off by OMB guidance sent out to agencies in the spring. From there the sequence goes: agency requests, then OMB review, then the President's Budget submission to Congress (usually February), then the congressional appropriations process, then enacted law, then agencies actually obligating the funds. That's six steps between "we want this" and "we can spend on this," and each step can add months.

Here's the part that matters for anyone trying to plan a technology project: an agency sketching out an IT investment in spring 2025 may not see appropriated dollars until late 2026, or later. Congress funds the government through 12 separate appropriations bills, and each agency's IT money flows through whichever bill covers that agency. Worse, standard appropriations are structured around a single fiscal year, even when the project itself is a three-year cloud migration or a five-year systems overhaul.

Annual funding windows and multi-year engineering reality simply pull in different directions, a structural mismatch baked into the calendar rather than a matter of anyone forgetting to plan ahead. That friction shows up in nearly everything downstream of it.

What continuing resolutions actually do to technology programs

A continuing resolution, or CR, is a stopgap that funds the government at prior-year levels when Congress hasn't passed the actual appropriations bills on time. CRs are far from a rare procedural hiccup. Congress has passed at least one in all but three fiscal years since 1977, which tells you the "temporary" label has been doing a lot of quiet, permanent work.

Between FY2010 and FY2025, there were 57 CRs, lasting anywhere from one day to 176 days. FY2025 itself never escaped CR territory: two short-term measures followed by a full-year CR signed March 15, 2025, that mostly just extended the FY2024 numbers forward. FY2026 was worse. Appropriations bills weren't enacted before the October 1 deadline, and a shutdown followed, lasting 43 days, the longest one on record.

What does a CR actually do to a technology program? A few concrete things. Agencies face significant constraints on initiating new programs that weren't already funded in the prior year's budget. Contracts for new modernization work can face serious delays in being awarded. Multi-year projects get stuck in a stop-start rhythm that quietly inflates both cost and risk, because restarting a paused contract is never free. And that 18-month planning gap from the last section? A CR just tacks more time onto it.

So the agency that started planning a modernization effort in spring may not spend a dollar on it for over two years, and depending on how the political winds shift in the meantime, it might never get built at the scope anyone originally imagined. CRs don't cancel projects outright; they erode them quietly, one delay at a time.

Where the bulk of federal IT money actually goes, and why it rarely goes to new things

Here's the number that explains almost everything else in this article: $83 billion, or 79% of planned FY2025 federal IT spending, went to operating and maintaining systems that already exist. That's according to the federal IT dashboard for CFO Act agencies, per GAO's July 2025 reporting. Flip that around and you get roughly $21 billion left for new development and modernization, spread across about 6,700 separate investments in FY2024 data.

An 80/20 split between keeping the lights on and building anything new has held for years now. This is the structure, not a bad budget cycle.

Why does maintenance eat more every year instead of holding steady? Older systems need more labor to keep running, full stop. Vendor support for aging platforms gets scarcer and pricier as fewer companies want to service twenty-year-old middleware. Security patching on legacy architecture soaks up staff hours that could otherwise go toward, well, anything else. So agencies asking for modernization money aren't competing against some neutral blank slate; they're competing against a baseline that's already spoken for.

And the variation between agencies tells its own story. In FY2025, Education's IT budget grew 30%, SSA's grew 12%, DHS's grew 9%. Meanwhile NASA fell 11%, USDA fell 7%. Some of that is political priority. A good chunk of it is just the gravitational pull of whatever legacy maintenance burden each agency happens to be carrying.

The legacy system trap that the maintenance budget creates

Follow the logic one step further and you find a loop, not a line. Deferred modernization raises the cost of maintaining what's already there; that higher maintenance cost eats into the modernization budget; the systems get older and harder to touch; the eventual cost of replacing them climbs even higher. Then repeat, every fiscal year, like a very expensive, very boring version of Groundhog Day.

GAO flagged 11 of the most critical legacy systems across government in need of modernization, spanning agencies from HHS to Treasury. As of February 2025, of the 10 GAO originally called out, only 3 had been completed. Of the remaining 7, just 4 had near-term completion plans. Two were five or more years out. One had no planned completion date at all, which is a polite way of saying nobody knows.

What does inaction cost? The ten most critical legacy systems run about $337 million a year just to keep operating, before a single line of modernization code gets written. And there's a workforce clock ticking underneath all of it: the COBOL programmer workforce, still essential to running many of these systems, averages 55 years old, with roughly 10% retiring annually. Institutional knowledge is walking out the door faster than anyone's writing it down.

Why does this keep happening if everyone can see the loop? Because the incentives inside an annual budget cycle reward exactly this behavior. A modernization effort that fails publicly ends careers; incremental maintenance spending is invisible, boring, and safe. Given that choice, a rational agency leader picks maintenance, every time. This is a predictable output of the machine doing exactly what it was built to do, more than any failure of leadership.

The Technology Modernization Fund: how a revolving model tries to break the cycle

The Technology Modernization Fund exists specifically to solve the problem the last section just laid out: modernization costs that show up all at once, front-loaded, in a system that only hands out money one year at a time. The model works like a loan. TMF gives agencies money for approved projects, and agencies pay it back out of the long-term savings the modernization generates, at least in theory, making the whole thing self-financing over time.

It funds cloud migration, data center consolidation, cybersecurity upgrades, workforce retraining, the exact categories of work that annual appropriations handle badly because they don't fit neatly into a single fiscal year.

Over its history, TMF has taken in appropriations and deployed funds across projects spanning multiple agencies. Proponents argue TMF-funded projects have performed substantially better than large government IT projects run through traditional appropriations. GSA credits the fund with meaningful efficiency gains and cost savings across participating agencies. The funded work tends to be unglamorous but nonetheless moves the needle for the people using these systems.

So naturally, the fund's authorization lapsed. TMF's congressional authorization lapsed, leaving future funding deeply uncertain. Proposals have circulated to put TMF on a more stable structural footing, aimed at loosening its dependence on the annual appropriations lever entirely.

Whether that fix survives the next round of budget fights is anyone's guess. But it's worth sitting with the irony: a mechanism built explicitly to escape the one-year funding trap is now itself at the mercy of the one-year funding trap.

Other funding mechanisms agencies use to work around annual appropriations limits

Table: Federal IT Funding Mechanisms Compared. Compares How It Works, Best Suited For, Key Structural Limit and Planning Reliability by Annual Appropriations, Technology Modernization Fund, Working Capital Funds and Supplemental / Emergency Funding.

TMF isn't the only escape hatch agencies use, just the most visible one.

Agency Working Capital Funds, or WCFs, are internal revolving accounts some agencies tap for IT investment that doesn't fit neatly into a single fiscal year. Legislation has established IT-specific WCFs at a subset of agencies to give CIOs more flexibility over technology investments. In practice, though, implementation has been uneven; legal and administrative snags have limited how much some agencies actually use them, and not every CFO Act agency has a fully operational IT WCF running today.

There are also governmentwide pools separate from any single agency's budget that OMB uses to fund cross-agency technology priorities and oversight work, operating alongside TMF. Supplemental appropriations show up occasionally too, emergency or one-off funding Congress approves outside the normal calendar for a specific push, pandemic-era digital services being the clearest recent example. These are useful when they happen but nobody can plan around them, since they depend entirely on political will lining up at the right moment.

And for state and local governments specifically, grants and intergovernmental transfers matter a lot, DHS cybersecurity grants and ARPA-funded broadband programs among them.

Most agencies end up layering all of this: annual appropriations to keep the lights on, WCFs where they exist for incremental upgrades, TMF or a supplemental for the bigger bets. Each mechanism drags its own compliance and reporting rules along with it, and knowing which pot of money applies to which project shapes not just what an agency can propose, but when it's even legally allowed to start.

How state and local government technology budgets differ from the federal model

State and local IT spending is projected at $160.2 billion in 2026, growing a modest 4 to 6% over 2025. Zoom into the broader State, Local, and Education market, and the numbers get more granular: of $138.9 billion budgeted across SLED in 2024, IT services accounted for $59 billion and software $13 billion; by 2025, those were expected to climb to $61 billion and $14 billion respectively.

The mechanics look pretty different from the federal picture, though. Many states run their fiscal year on a different calendar than the federal October 1 start, which shifts the whole procurement calendar out of sync with federal timing. Some states also budget across longer cycles rather than strictly annual ones. That gives them more planning stability than the federal government's yearly scramble, but it cuts the other way too: less room to pivot mid-cycle if a new priority suddenly matters. And because states generally cannot lean on deficit spending the way the federal government can, big capital IT projects need explicit funding, usually through bonds or dedicated capital appropriations.

Federal grants still loom large here. DHS cybersecurity grants, broadband funding, ARPA-era pandemic dollars, all of it has flowed down to state and local technology budgets, which means even local governments end up tethered to federal budget timing whether they like it or not.

One trend worth watching: the "whole of state" approach, where states coordinate IT purchasing across agencies and with local governments to get economies of scale and a more consistent security posture. It's a real shift in how these budgets get planned and approved, though it runs into the same wall the federal government does at the local level, where individual counties and municipalities often keep their own separate budget cycles, technology offices, and vendor relationships. That fragmentation is a big part of why the SLED market is genuinely more complicated to navigate than the federal one, despite being smaller in total dollars.

What the budget structure means for how and when technology priorities actually shift

Put all of this together and the pace of government technology adoption reveals itself as a structural matter, wired directly into the budget calendar and the appropriations rules described above, rather than a culture problem.

Big shifts in priority tend to need one of three things to happen. A crisis or mandate that creates enough political urgency to unlock supplemental or emergency funding, the way past cybersecurity incidents have forced security mandates or the pandemic forced a sprint on digital services. A sustained multi-year appropriations line that somehow survives the political cycle intact, which is rare; A large one-time injection into TMF was the exception, not the rule. Or an administration-level directive that reshapes OMB's guidance before agencies even draft their spring budget requests, which then takes 18 months or more to actually show up as real spending.

What's clearing that bar right now? DoD's FY2026 request included $13.4 billion for autonomy and AI, $16 billion for cybersecurity, and $150 million for legacy modernization, numbers that suggest those categories currently have enough political weight to survive the appropriations gauntlet. AI and zero trust are turning up across agency budget requests too. Whether those requests survive the next CR, the next administration change, or the next round of spending pressure remains the open question, separate from whether agencies want them.

For vendors selling into this market, the budget calendar effectively is the sales cycle; knowing when an agency can legally obligate funds, and when it legally can't, matters just as much as knowing what they're shopping for. For anyone watching from outside, the gap between a budget request and an enacted appropriation, and the second gap between an enacted appropriation and an actual obligated dollar, is where most technology priorities quietly stall out, not for lack of ambition, but because the calendar simply didn't cooperate.

Sources

  1. washingtontechnology.com
  2. gao.gov
  3. intelliworxit.com
  4. gao.gov
  5. files.gao.gov
Filed underCIO Strategy

More in CIO Strategy